CVE-2022-34253
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.91% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-91
- Affected
- adobe/commerce · magento/magento
- Source
- psirt@adobe.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.